Fossil

Diff
Login

Diff

Differences From Artifact [df0983ab84]:

To Artifact [e25fb1dca8]:


214
215
216
217
218
219
220
221
222


223
224
225
226
227
228
229
214
215
216
217
218
219
220


221
222
223
224
225
226
227
228
229







-
-
+
+







affecting the <tt>/login</tt> page only. If you're using this setting,
you should migrate to the new setting as soon as possible, because the
old setting allows multiple ways of defeating it.

<b id="rloop">WARNING:</b> Enabling HTTPS redirects at the Fossil repo
level while running Fossil behind an HTTPS proxy can result in an
infinite redirect loop.  It happens when the proxy mechanism presents
"`http`" URIs to Fossil, so Fossil issues a redirect, so the browser
fetches the page again, causing Fossil to see an "`http`" URI again, so
"<tt>http</tt>" URIs to Fossil, so Fossil issues a redirect, so the browser
fetches the page again, causing Fossil to see an "<tt>http</tt>" URI again, so
it issues a redirect...'round and 'round it goes until the web browser
detects it's in a redirect loop and gives up. This problem prevents you
from getting back into the Admin UI to fix it, but there are several
ways to fix it:

  #  <p><b>Reset via CLI.</b> You can turn the setting back off from the
     CLI with the command "<tt>fossil -R /path/to/repo.fossil set